Fooder — Malware Profile
Fooder is a custom 64-bit C/C++ loader used by MuddyWater that can decrypt and reflectively load embedded payloads such as a go-socks5 proxy utility, the open-source HackBrowserData infostealer, or the MuddyViper backdoor. Fooder has frequently masqueraded as an entertainment executable, such as the Snake game (e.g., `Snake_Game.exe`).
MITRE ATT&CK techniques (7)
- T1027 Obfuscated Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1106 Native API
- T1134.001 Token Impersonation/Theft
- T1140 Deobfuscate/Decode Files or Information
- T1620 Reflective Code Loading
- T1678 Delay Execution